magicbug cloudlog CVE Vulnerabilities (6)

CVEs: 6 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting magicbug cloudlog (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-44065 Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter. [email protected] 9.8 0.35% 2025-12-26 2026-06-17
CVE-2025-64084 An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a malicious payload, which is then concatenated directly into a raw SQL query in the vucc_qso_details function. [email protected] 5.4 0.27% 2025-11-14 2026-06-17
CVE-2024-48259 Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. [email protected] 7.3 0.86% 2024-10-14 2026-06-17
CVE-2024-48255 Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. [email protected] 9.8 0.43% 2024-10-14 2026-06-17
CVE-2024-48253 Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. [email protected] 9.8 0.43% 2024-10-14 2026-06-17
CVE-2024-45999 A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter. [email protected] 9.8 0.36% 2024-10-01 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence